Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\clr_optimization_v2.0.50727_32Sys] 'Start' = '00000002'
- '<SYSTEM32>\svchost.exe' -k netsvcs
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\Com\svchost.exe
- %ALLUSERSPROFILE%\Application Data\Mozilla\UV9FXlFbb1NfWVQPBg.bin
- <SYSTEM32>\Com\svchost.exe
- %ALLUSERSPROFILE%\Application Data\Mozilla\UV9FXlFbb1NfWVQPBg.bin
- из <Полный путь к вирусу> в <Полный путь к вирусу>1
- 'da###n-auto.com':80
- '87.##6.210.109':443
- da###n-auto.com/HwjgHWmf7BNBaLngCgDS2woGM5/oiNLddeuQ9LlimXyNhKy3/zyl9DMhBE9Y/cZhjQOArY/KTRhRweeMloCwheBPLbCYUxbCyxSOVUtCE634KtpWVjGelmZBTOG9FmAb17Py7lxsMUp9.gif
- da###n-auto.com/aGhAcEDJIE41iv.4sZCdI/5tEDlKxWfDUSnVoPaUqnKKqV3HvwnYq5oTKCuzRdCukNbRV7A7DSmepCOnEZOte7appqbRbw6ai8-aOyXTq.php
- da###n-auto.com/TzOwoDyMmyPb5gjcSOaUs7k0WEsCdFtiGFhYEG8H3JXm7.E/MLtyJNlO9bqMjhTdhv4WJN0PMjeHmZ7BIKmLzk.SyVXjTA.R/DQ9MqysMQ.rSuuR44j2W48Ldf2nkQTU1Jfhhu-2H7SR4azV33HxZT4bEXEbfU4xuICy4bviAh.html
- da###n-auto.com/QOdSSvQEg6TzfpU48h/rY-8jXaDV4zuUKxW8j/PkNVwp/fedkRIsOc/y9nJ6Qh-oaCTLJeYNgZTk8GXCsw.IafCvME.php?wh#######################################################################################
- DNS ASK da###n-auto.com
- ClassName: 'Shell_TrayWnd' WindowName: ''